Alerts

Aruba Security Updates – 31 August 2023

Aruba has released security updates to address multiple vulnerabilities affecting HPE Aruba Networking Switches. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, cause denial of service attacks, perform cross-site scripting (XSS) attacks, and gain access to the affected products. Sample of the addressed vulnerabilities: 1. Unauthenticated Stored Cross-Site Scripting Vulnerability in […]

Aruba Security Updates – 31 August 2023 Read More »

VMware Security Update – 31 August 2023

VMware has released a security update to fix a vulnerability across multiple versions of VMware Tools. The addressed vulnerability could allow the attacker with man-in-the-middle (MITM) network positioning between vCenter server and the virtual machine to bypass SAML token signature verification on the affected versions of VMware Tools. SAML Token Signature Bypass Vulnerability (CVE-2023-20900): CVSS:

VMware Security Update – 31 August 2023 Read More »

Trend Micro Security Update – 30 August 2023

Trend Micro has released a security update to fix several reflected cross-site scripting (XSS) vulnerabilities at Trend Micro Mobile Security (Enterprise) version 9.8. The severity of the addressed vulnerabilities could allow the remote attacker to perform reflected cross-site scripting attacks and steal the victim’s cookie-based authentication credential from the affected system by persuading the victim

Trend Micro Security Update – 30 August 2023 Read More »

Mozilla FireFox Security Updates – 30 August 2023

Mozilla has released an updated Firefox version 117, and Firefox ESR versions 102.15, 115.2 to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, obtain sensitive information, perform a denial of service attack, bypass security restrictions, or gain access to the affected system by persuading the victim to visit

Mozilla FireFox Security Updates – 30 August 2023 Read More »

VMware Security Updates – 30 August 2023

VMware has released security updates to fix multiple vulnerabilities in VMware Aria Operations Networks, and VMware Horizon Server. The addressed vulnerabilities could allow the attacker to gain access, execute arbitrary code, or bypass security restrictions by sending a specially crafted request to VMware Aria Operations Networks affected versions. Sample of the addressed vulnerabilities: 1. VMware

VMware Security Updates – 30 August 2023 Read More »

Microsoft Edge Security Update – 27 August 2023

Microsoft has released an updated Microsoft Edge stable version (116.0.1938.62) to fix multiple vulnerabilities. The addressed vulnerabilities could allow the remote attacker to elevate the privilege or execute arbitrary code on the affected system. Sample of the addressed vulnerabilities: 1. Microsoft Edge Code Execution Vulnerability (CVE-2023-4427): CVSS: 8.8 Attack Vector: Network Attack Complexity: Low Privileges

Microsoft Edge Security Update – 27 August 2023 Read More »

Cisco Security Updates – 24 August 2023

Cisco has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to bypass security restrictions, read or overwrite files, or perform denial of service attacks on the affected products by sending a specially crafted request. Sample of the addressed vulnerabilities: 1. Cisco Firepower 4100 Series, Firepower 9300

Cisco Security Updates – 24 August 2023 Read More »

Google Chrome Security Update – 23 August 2023

Google has released an updated Chrome version (116.0.5845.110/.111) for Windows, and (116.0.5845.110) for Linux, and Mac to fix several vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the addressed vulnerabilities: Google

Google Chrome Security Update – 23 August 2023 Read More »

Aruba Security Updates – 23 August 2023

Aruba has released security updates to fix several vulnerabilities in EdgeConnect SD-WAN Orchestrator. The addressed vulnerabilities could allow the remote attacker to gain access, obtain information, bypass security restrictions, or trigger cross-site scripting (XSS) attacks on the affected product. Sample of the addressed vulnerabilities: 1. HPE Aruba Networking EdgeConnect SD-WAN Orchestrator Cross-Site Scripting (CVE-2023-37423): CVSS:

Aruba Security Updates – 23 August 2023 Read More »

Microsoft Edge Security Update – 20 August 2023

Microsoft has released an updated Microsoft Edge stable version (116.0.1901.200) to fix multiple vulnerabilities in Microsoft Edge (Chromium-based). The addressed vulnerabilities could allow the remote attacker to obtain sensitive information or gain elevated privileges on the affected system. Sample of the addressed vulnerabilities: Microsoft Edge Privilege Escalation Vulnerability (CVE-2023-36787): CVSS: 8.8 Attack Vector: Network Attack

Microsoft Edge Security Update – 20 August 2023 Read More »

Cisco Security Updates – 17 August 2023

Cisco has released security updates to fix multiple vulnerabilities across multiple products. The addressed vulnerabilities could allow the attacker to gain access, obtain information, perform cross site scripting, or gain elevated privileges on the affected products. Sample of the addressed vulnerabilities: 1. Cisco Unified Communications Manager SQL Injection (CVE-2023-20211): CVSS: 8.1 Attack Vector: Network Attack

Cisco Security Updates – 17 August 2023 Read More »

Ivanti Security Update – 16 August 2023

Ivanti released a security update to fix multiple vulnerabilities affecting Ivanti Avalanche versions 6.4.1.207, 6.4.0, and older. The addressed vulnerabilities could allow the remote attacker to gain access, execute arbitrary code, and trigger a buffer overflow attack on the affected product by sending a specially crafted request. Sample of the addressed vulnerabilities: 1. Ivanti Avalanche

Ivanti Security Update – 16 August 2023 Read More »

Google Chrome Security Update – 16 August 2023

Google has released an updated Chrome version (116.0.5845.96/.97) for Windows, and (116.0.5845.96) for Linux, and Mac to fix several vulnerabilities. The addressed vulnerabilities could allow the remote attacker to execute arbitrary code, bypass security restrictions, and gain access to the affected system by persuading the victim to visit a specially crafted website. Sample of the

Google Chrome Security Update – 16 August 2023 Read More »